MEDIUM
CVE-2026-84048
CVSS
6.3
Description
Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.2 - The TUS endpoint allows arbitrary file uploads, however neither file name nor file extension are under attacker control. Code execution requires non-standard server configuration.
Weakness (CWE)
CWE-284
Improper Access Control
EPSS Score
0.31%
Probability of exploitation in next 30 days
24.1th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.